CVE-2018-9173
MEDIUMGetSimple CMS 3.3.13 - Cross-Site Scripting via uploadify.swf movieName Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-9173. PoCs published by Sureshbabu Narvaneni.
AI-analyzed exploit summary This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.13 via the 'movieName' parameter in the SWF file. The PoC includes URLs that trigger JavaScript alerts and cookie theft.
Description
Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inject arbitrary web script or HTML, as demonstrated by the movieName parameter.
Exploits (1)
This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.13 via the 'movieName' parameter in the SWF file. The PoC includes URLs that trigger JavaScript alerts and cookie theft.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N